Showing posts with label data security. Show all posts
Showing posts with label data security. Show all posts

Monday, December 20, 2010

Holiday Travel and IT Security Risks

Posted by Mark Brousseau

Tis the season to be jolly – and to leave sensitive corporate information behind at the airport!

According to telephone interviews with the lost property offices of 15 UK airports, including Heathrow and Luton, over 5,100 mobile phones and 3,844 laptops have been left behind so far this year; with the majority still unclaimed and many more expected to be left over the Christmas holiday peak season. This figure is likely to be just the tip of the iceberg as ABTA expect over 4 million people to be travelling over this period, and the overall figures do not take into account all those devices that were stolen, or kept by the ‘lucky’ finder.

The survey, carried out by Credant Technologies, also found that in the majority of cases, those devices that aren’t reclaimed are then either sold at auction or donated to charities. However the fact is that these devices may still contain information that could be available for the new owner. With ID theft from mobile phones and other lost devices at an all time high, users should really take special care this Christmas when travelling.

According to a representative at Luton Airport, the most common place devices are forgotten is at the security check point as it’s a very pressured environment with numerous distractions. Often, once the travelers have boarded the plane and left the country it’s just too expensive to return for the device, which in most instances will be covered by insurance, resulting in the majority going unclaimed.

But the device’s value is the last thing organisations should be worrying about, explains Seán Glynn, vice president at Credant Technologies, “What is much more concerning are the copious volumes of sensitive data these devices contain – often unsecured and easily accessed. Without protecting mobile phones, laptops and even USBs with something even as basic as a password, a malicious third party can have easy access to the corporate network, email accounts and all the files stored on the device including the contact lists. Users also store such things as passwords, bank details and other personal information on the device making it child’s play to impersonate the user and steal their identity – both personal and corporate.”

Credant Technologies provides the following eight tips to secure corporate information during holiday travel:

1. As you leave - whether it’s the check-in desk, security check point, or even the train station, make sure you take everything with you, including your mobile devices. A few seconds to check could potentially save you hours of frustration and embarrassment.

2. Protect your mobile device: with at least a password (and ensure that it is a strong one, containing letters, numbers and symbols). Better still, use an encryption solution so that even if your device is left behind, the data on it is not accessible to anyone who finds it.

3. Don’t elect to automatically complete online credentials, such as corporate network log in details, so that if you and your device should become separated, it cannot operate without you.

4. Back-up your device and remove any sensitive information that you do not need. If it’s not there it can’t be breached.

5. As in tip 4, remove SMS and emails that you don’t need anymore - you’d be sur­prised how many people keep their default password emails on their mobiles and other hugely sensitive information like PINs, bank account details or pass­words!

6. Don't leave your mobile device open to access (e.g. leaving Bluetooth or WiFi turned on) somewhere visible and unsecured.

7. Include your name and contact details in the device so that, if it should be lost, it can easily be returned to you. Some operators have a registration service to facilitate this.

8. Finally, speak to your IT department before you leave the office this year – that’s what they’re there for. They’ll help make sure your device is better protected should it find itself languishing all alone at the airport.

What do you think?

Monday, November 29, 2010

There’s a Bounty on your Applications

By Anthony Haywood of Idappcom

In the last year there have been a number of organizations offering rewards, or ‘bounty’ programs, for discovering and reporting bugs in applications. Mozilla currently offers up to $3,000 for crucial or high bug identification, Google pays out $1,337 for flaws in its software and Deutsche Post is currently sifting through applications from ‘ethical’ hackers to approve teams who will go head to head and compete for its Security Cup in October. The winning team can hold aloft the trophy if they find vulnerabilities in its new online secure messaging service – that’s comforting to current users. So, are these incentives the best way to make sure your applications are secure?

At Idappcom, we’d argue that these sorts of schemes are nothing short of a publicity stunt and, in fact, can be potentially dangerous to an end user's security.

One concern is that, by inviting hackers to trawl all over a new application prior to its launch, just grants them more time to interrogate it and identify weaknesses which they may decide is more valuable if kept to themselves. Once the first big announcement is made detailing who has purchased the application, with where and when the product is to go live, the hacker can use this insight to breach the system and steal the corporate jewels.

A further worry is that, while on the surface it may seem that these companies are being open and honest, if a serious security flaw were identified would they raise the alarm and warn people? It’s my belief that they’d fix it quietly, release a patch and hope no-one hears about it. The hacker would happily claim the reward, promise a vow of silence and then ‘sell’ the details on the black market leaving any user, while the patch is being developed or if they fail to install the update, with a great big security void in their defences just waiting to be exploited.

Sometimes it’s not even a flaw in the software that can cause problems. If an attack is launched against the application, causing it to fail and reboot, then this denial of service (DOS) attack can be just as costly to your organisation as if the application were breached and data stolen.

A final word of warning is that, even if the application isn’t hacked today, it doesn’t mean that tomorrow they’re not going to be able to breach it. Windows Vista is one such example. Microsoft originally hailed it as ‘it’s most secure operating system they’d ever made’ and we all know what happened next.

A proactive approach to security
IT’s never infallible and for this reason penetration testing is often heralded as the hero of the hour. That said technology has moved on and, while still valid in certain circumstances, historical penetration testing techniques are often limited in their effectiveness. Let me explain - a traditional test is executed from outside the network perimeter with the tester seeking applications to attack. However, as these assaults are all from a single IP address, intelligent security software will recognize this behavior as the IP doesn’t change. Within the first two or three attempts the source address is blacklisted or fire walled and all subsequent traffic is immaterial as all activities are seen and treated as malicious.

An intelligent proactive approach to security
There isn’t one single piece of advice that is the answer to all your prayers. Instead you need two and both need to be conducted simultaneously if your network’s to perform in perfect harmony: application testing combined with intrusion detection.

The reason I advocate application testing is, if you have an application that’s public facing, and it were compromised the financial impact to the organization could potentially be fatal. There are technologies available that can test your device or application with a barrage of millions upon millions of iterations, using different broken or mutated protocols and techniques, in an effort to crash the system. If a hacker were to do this, and caused it to fall over or reboot, this denial of service could be at best embarrassing but at worst detrimental to your organization.

Intrusion detection, capable of spotting zero day exploits, must be deployed to audit and test the recognition and response capabilities of your corporate security defences. It will substantiate that, not only is the network security deployed and configured correctly, but that it’s capable of protecting the application that you’re about to make live or have already launched irrespective of what the service it supports is – be it email, a web service, anything. The device looks for characteristics in behavior to determine if an incoming request to the product or service is likely to be good and valid or if it’s indicative of malicious behavior. This provides not only reassurance, but all important proof, that the network security is capable of identifying and mitigating the latest threats and security evasion techniques.

While we wait with baited breath to see who will lift Deutsche Post’s Security Cup we must not lose sight of our own challenges. My best advice would be that, instead of waiting for the outcome and relying on others to keep you informed of vulnerabilities in your applications, you must regularly inspect your defences to make sure they’re standing strong with no chinks. If you don’t the bounty may as well be on your head.

What do you think?

Tuesday, November 23, 2010

Network Security Facing Dual Challenge

By Dan Joe Barry, Napatech

Network security systems are under pressure. You might not be experiencing it yet, but you will soon. The dual challenge of dealing with more attacks at higher speeds threatens to undermine the stability of the most important commercial platforms of the 21st century; namely the Internet.

What can be done to address these challenges and avert the economic impact of an Internet collapse?

For many, the Internet is synonymous with web browsing, email and chat. But, the Internet and, IP-based networks in general, are now the foundation for a host of commercial services with significant impact on our daily lives.

On-line shopping is familiar to many, as is net-banking, but the financial world has now become reliant on the Internet for executing banking and investment transactions, sometimes thousands per second. Government services have also moved on-line. The Internet is used extensively in education and healthcare to provide distance services and expert consultation. The advent of cloud computing means that corporations will be more reliant than ever on the Internet to support their business.

In short, without the Internet, our lives would come to a grinding halt.

The development of the Internet as a commercial platform has not gone un-noticed by criminal organizations, which are exceptionally innovative in finding new ways of generating revenue! They have displaced the amateur hacker enthusiasts as the key threat to the Internet.

The open and global advantages of the Internet are now suddenly disadvantages as cybercriminals can attack from any location in the world, beyond the reach of domestic law enforcement agencies.

To understand the scope of the network security challenge, consider figures from Trend Micro, a leading provider of network security solutions, who have reported an explosive growth in the number of unique malware samples (i.e. types of attack) over the last 20 years.

Network security system vendors are struggling to respond to these new attacks as quickly as they occur. In a sense, they are playing a cat-and-mouse game with adversaries who are at least as intelligent and innovative at exploiting weaknesses in networks and applications, as they are at detecting attacks.

Higher data rates compound the challenge facing network security system vendors. IP networks are now being upgraded from 1 Gbps to 10 Gbps link speeds with 40 Gbps and 100 Gbps on the horizon. At 1 Gbps, a network security system needs to analyze up to 1.5 million packets per second. At 10 Gbps, this becomes 15 million packets per second. This is per port and only in 1 direction.

The challenge for network security system vendors is to ensure that their systems:

• Can handle up to 15 million packets per second per port in each direction

• Have the necessary processing power and memory to analyze packets in real-time

• Can scale to detect millions of new malware samples and higher line rates

The traditional approach to building network security systems is to build customized hardware including ASIC chip development. However, with the exponential growth in malware and higher line-rates, network security systems need to scale in both terms of data handling and computing power on a regular basis. This in turn means that the lifetime of a product revision will be shorter.

This begs the question: can network security system vendors keep up and have they got the deep pockets required to fund custom hardware and chip development on a regular basis?

It also leads to the question: is there another way?

High-performance network security systems can be based on standard, off-the-shelf PC servers when these are combined with Intelligent Real-time Network Analysis adapters for handling full line-rate data.The advantage of this approach is that it takes advantage of the strong roadmap of PC server and CPU chip vendors who are updating their performance and the number of processing cores they support on a yearly basis.

Basing high-performance network security system development on standard PC servers with Intelligent Real-time Network Analysis adapters provides a path to addressing the dual challenge of more malware at higher line-rates. It provides a cost-efficient, yet high-performance model that allows network security system vendors to focus on their expertise, namely combating cybercriminals and protecting the vital commercial platform that the Internet has become.

What do you think?

Monday, November 22, 2010

Congress Should Amend COICA

Last week, the U.S. Senate Judiciary Committee unanimously voted to approve the "Combating Online Infringements and Counterfeits Act" (COICA). The bill would allow the U.S. Attorney General to obtain a court order disabling web domains deemed to be “dedicated to infringing activities.”

Intellectual property scholars at the Competitive Enterprise Institute praised the bill in principle but warned that the legislation's current provisions threaten free speech and lack crucial safeguards to protect against the unwarranted suspension of Internet domain names.

“Combating piracy and counterfeiting on the Internet should be a priority for Congress, but care should be taken to ensure that legislative attempts to protect intellectual property rights do not harm other vital interests,” said Ryan Radia, CEI Associate Director of Technology Studies. “COICA’s overbroad definition of Internet sites 'dedicated to infringing activities' risks ensnaring legitimate websites. The bill also lacks a provision ensuring that Internet site operators targeted by the Attorney General have an opportunity to defend their site in an adversary judicial proceeding."

Over three dozen law professors recently submitted a letter to the U.S. Senate raising concerns about COICA, arguing that the bill suffers from “egregious Constitutional infirmities.”

“In its current form, elements of COICA raise serious First Amendment concerns,” said Hans Bader, CEI Senior Attorney. “If enacted, the law will not likely survive a constitutional challenge.”

Radia argued that Congress should amend COICA to provide for more robust safeguards, including:

• Providing a meaningful opportunity for Internet site operators to challenge before a federal court an Attorney General’s assertion that their site is “dedicated to infringing activities” prior to the domain name's suspension;

• Requiring that the Attorney General, prior to commencing an in rem action against a domain name, make a reasonable attempt to notify the site’s actual operator;

• Clarifying the definition of an Internet site “dedicated to infringing activities” to ensure that Internet sites with cultural, artistic, political, scientific, or commercial value that facilitate infringing acts by third parties do not face domain name suspension if their operators comply with legitimate takedown requests;

• Instructing the Department of Justice and federal prosecutors not to request that domain name registrars, registries, or service providers suspend domain names that have not been deemed to be “dedicated to infringing activities” by a federal court;

• Requiring the Department of Justice to compensate domain name registrars, registries, and service providers for any reasonable costs they incur in the course of disabling infringing domain names.

What do you think?

Tuesday, October 26, 2010

E-Discovery: Addressing the Risks

By Rich Walsh of Viewpointe

At the heart of many risks facing companies today lurks e-discovery – the locating and accessing of electronically stored information (ESI) for purposes of litigation. ESI can be any electronically stored information – documents, emails, databases, etc. – potentially for use as evidence by lawyers in legal cases.

Compounding the risk to companies is the volume of data subject to e-discovery. In fact, the Association of Certified E-Discovery Specialists, a group dedicated to dealing with this problem, calls the deluge of electronically stored material used as evidence in civil actions the single biggest storyline in the legal world today.

In a recent cross-industry report commissioned by the Deloitte Forensic Center, “E-Discovery: Mitigating Risk Through Better Communication,” just 43 percent of the respondents felt that their companies were somewhat up for the e-discovery challenge. The report notes that in the e-discovery process legal, IT and other departments – those that don’t normally work together – are often thrown together “in a room” to do a difficult job under quite a bit of pressure. And with a lack of common language and systems among these groups, it only further muddies the process.

Where is all of this leading? The Deloitte report found that 49 percent of respondents expect their company’s IT department to have to work more on e-discovery efforts in the near future. So, on top of IT’s workload and limited budgets, adding new e-discovery work will further challenge their priorities. In preparation, companies will need to figure out, sooner than later, where (and even if) they have stored and can easily retrieve everything they might need to produce.

I’d love to hear from TAWPI members as how your companies may be preparing for this challenge. Any tips for colleagues? Share with us.

Rich Walsh is president, Document Archive & Repository Services at Viewpointe. He has more than 25 years of operational information technology experience.

Friday, September 3, 2010

The buck stops here: the role of CEOs in data security

Ray Bryant, CEO of idappcom explains why the big chair in most organizations can carry a lot more responsibility than you might think:

You would never consider purchasing an inferior accounting system that opens your organization up to financial loss through bad record keeping - potentially putting it out of business and generating the wrath of shareholders and other stakeholders this would cause.

Yet many managers will cheerfully purchase an inferior, but lower-cost, IT security defense system for their company, and later regret that purchase when hackers successfully compromise their firm's data, ruining the firm's reputation and opening it up to financial penalties that could well put it out of business.

Welcome to the business horror that is a data breach.

As with all technology-driven issues, to make a decision on which IT security system to go with, the CEO (and his team) must first understand where the problem is - in this case, where a data breach originates.

While the popular media perception is that IT security defenses are there to protect an organization's digital assets from external attack, the reality is that a large number of incidents are the result of internal threats compromising the firm's data. However, a quick scan through the constant stream of media reports about the unfortunate companies - and their equally unfortunate senior managers - who are put through the data breach wringer, will frequently reveal that the data breach was due to an internal hack.

Beware, internal does NOT always mean the person is physically in your premises. It just means they are internal to your systems. More and more cases revolve around a hacker gaining entry through ‘back doors’ into your computer, they could be anywhere on the net certainly outside your jurisdiction even if you ‘caught’ them.

But it gets worse, as an increasingly common hacker methodology is to crack the security of one company and use that system as a launch pad to hack into other systems. Ever had an email returned “undeliverable” and you did not send it? You’ve been hacked and probably been sending emails with attacks/backdoors in them to your entire contact list, and a list the attacker wanted to send to. You may now be a spammer as well.

The liability for all attacks including ‘secondary’ attacks lies with the CEO who has allowed - either directly or indirectly - his/her company systems to be misused in this manner.

The problem of inter-linked computer systems is a growing one, as the larger the company, the more reliance it places on computers and connections. These connections are the lifeblood of the cybercriminals, who tap into the fact that the privilege levels of user IDs that interconnect with third-party systems invariably tend to be higher than direct external accounts. Put simply, this means that an internal account from company A will have a much greater degree of access to company B's computer systems than an individual’s external account to company B's systems.

It's all about trust - as today's IT professionals will confirm, the interconnectivity between companies is now so pervasive it increases the risk profile of inter-system IDs to much higher levels than most people are aware of. This is the stuff that lawsuits are made of and can you guess who carries the can for these problems? That's right - the CEO and his/her senior management.

In many `hacked' systems, a risk analysis/penetration test - no matter what the size of company concerned - would normally have revealed the weaknesses in its security that the hacker(s) exploited. Questions that are asked by a risk assessor include what are the system's entry points and what data is accessible, and, of course, whether fraudulent transactions can be originated.

Issues addressed by the risk assessor include whether the data is classified, and what levels of protection are used in which areas of the system. Other topics up for discussion include whether the organisation has the level of expertise available, internally or externally, that understands the security requirements, and whether the security devices are configured to meet the organizational needs.

We often find that following a data breach, it becomes apparent that not only was the organisation's security lacking and poorly configured, but there is often a lack of understanding amongst senior management as to what the role of IT security is within the business. This brings us back to the popular misconception that IT security systems are there to protect the company IT resources against external attacks, ranging from fraudsters all the way to cybercriminal phishing attack vectors.

The reality, as our research team has discovered, is that fraud normally comes from the inside - either a rogue employee generates the fraud or, increasingly, a hacker who has got through a security device and installed a backdoor on the system that now allows them to freely move around, monitor and appear to be an internal person. You don’t know they are there until it’s too late.

One of the most interesting aspects of dissecting a given security breach is how often, apart from the breach itself, the hacker has been able to get inside the company's IT systems. This has the potential to be even more damaging than it may at first appear because in the build up to the fraud and subsequent data breach, most cybercriminals operate in `stealth mode' and can therefore milk the company's finances for a lengthy period before they are rumbled by conventional IT audit methodologies. This means that, for almost all organizations, enhancing the IT security of the company - by ensuring it is maintained as up to date as automatically possible - is an absolute necessity, and not the IT luxury that many senior managers perceive it to be.

Put simply, this means that spending hundreds of thousands of dollars, pounds or Euros on a security system, plugging it in and switching it on - then presuming your company is secure - is a totally inadequate approach, because it usually results in relatively poor levels of protection for your organisation as the threats from criminals are constantly changing. Configuration, constant evaluation and constant updating of security rules are essential to the IT security of a business. Of course, the degree to which protection is needed is a matter of balancing risk and cost, and this equation is a unique business decision as with any other senior management process.

Assuming that the ROI charts have been prepared and the risk analysis process completed, the next step on the road to deploying effective IT security is to ensure it is working properly, and stays that way. This is a stumbling block that many companies fall at, as frequent verification checks on the efficiency - and efficacy - of an IT security platform need to be made. Whatever the system - and whatever the smoke and mirrors from the 'theory' sellers - there is only one way to validate against KNOWN threats, and that is to play those threats in a controlled way, through the company's actual live prevention set-up. Test, review, and test again - not in the lab, but in a real business environment, where actual threats exist and can be tested against. It's my supposition that a good CEO should also look for the IT teams ability to not only define the threat but also have a solution that can be deployed to meet that threat in as short a timeframe as possible.

Our own tests suggest, in fact, that one of the most popular (free) security systems will spot very few threats without the necessary configuration, and new security rules issued by the vendor each month represent about 10% of the actual new, very relevant, threats that appear each month. This issue arises because configuration needs a method of evaluation to ensure its efficacy and, in the event that faults are discovered during the review process, to allow the configuration to be revised and new rules introduced to remediate the problem; immediately not months later.

In an ideal world, it would be possible to remediate all threats, but in the real world, this would significantly slow the IT system down, meaning that a compromise between threat checking and system performance is usually required. By using an optimum configuration validation system, you can get the best of both worlds. The amount of IT security your organisation actually needs can only be judged by an effective risk analysis process, followed by a cost/benefit exercise.

It's also worth noting that in most countries - particularly the US and member states of Europe - there is now clear legislation and/or good corporate governance requirements that make the CEO clearly responsible for any security breaches.

CEOs are not only responsible for the effect of attacks to their own IT systems, but they are responsible for hackers who use their system to attack others. The growing trend for major corporations systems - particularly in manufacturing and distribution - to link their computers together using electronic data interchange (EDI) systems, with very little manual intervention, opens yet another `backdoor' for hackers to spread their activities. As with any pain, it comes after the attack. Your defences need to be up at all times, not just when audited or it will be the audit that shows you where you may have been slowly bleeding to death.

What do you think?

Thursday, June 3, 2010

Perception of data security at odds with reality

Posted by Mark Brousseau

Nearly three-quarters of organizations believe they have adequate policies in place to protect sensitive, personal information, yet more than half have lost sensitive data within the past two years — and nearly 60 percent of those organizations acknowledge data loss as a recurring problem, according to findings of a global study by Accenture.

The study reveals a startling difference between organizations’ intentions regarding data privacy and how they actually protect sensitive personal information, such as name, address, date of birth, race, National ID/social security number and medical history. The study was conducted in conjunction with the Ponemon Institute, a privacy, protection and information security research firm.

“The volume of sensitive personal information being collected and shared by organizations has grown exponentially in recent years, making data protection a critical business issue and not just a technology concern,” said Alastair MacWillson, managing director of Accenture’s Security practice. “Our study underscores the importance of taking a comprehensive approach to data privacy and protection, one that closes the gaps between business strategy, risk management, compliance reporting and IT security.”

Global Business Findings

Fifty-eight (58) percent of business respondents have experienced at least one data security breach over the past two years, yet 73 percent said their organization has adequate policies to protect the personally identifiable information it maintains.

While 70 percent agreed that organizations have an obligation to take reasonable steps to secure consumers’ personal information, there are discrepancies in their commitments for doing so:

• Forty-five (45) percent of respondents were unsure about or actively disagreed with granting customers the right to control the type of information that is collected about them.

• Forty-seven (47) percent were unsure about or disagreed with customers having a right to control how this information is used.

• Nearly half also did not believe it was important or very important to: limit the collection (47 percent) or sharing (46 percent) of sensitive personal customer information; protect consumer privacy rights (47 percent); prevent cross-border transfers of personal information to countries with inadequate privacy laws (47 percent); prevent cyber crimes against consumers (48 percent); or prevent data loss or theft (47 percent).

• The study revealed that the biggest causes of data loss are internal — problems presumably well within an organization’s ability to detect and correct. For instance, business or system failure (57 percent) and employee negligence or errors (48 percent) were cited most often as the source of the breaches; cyber crime was cited as a cause of only 18 percent of security breaches.

While many organizations believe that complying with existing regulations is sufficient, it appears that compliance alone may not be enough to protect sensitive data. For instance, 70 percent of respondents said they regularly monitor privacy and data protection regulatory compliance requirements, yet data breaches have occurred in 58 percent of organizations polled.

Thursday, February 4, 2010

Don't Turn Cybersecurity into a Bureaucracy

Posted by Mark Brousseau

New legislation being discussed in Washington runs the risk of turning cybersecurity into a bureaucracy. Wayne Crews, vice president for policy at the Competitive Enterprise Institute, thinks a better solution is to enhance private sector practices. He explains:

The House of Representatives is considering HR 4061, the Cybersecurity Enhancement Act. A solid Cybersecurity Enhancement Act might read “Title I: Stop losing federal laptops.” That’s too flip, but consider that there are cybersecurity risks to cybersecurity legislation.

Vulnerabilities in the government’s information security policies and the need to “bring government into the 21st century” have long been noted. But given the constant temptation by politicians in both parties to meddle with cybersecurity policy by steering research and development in unnatural directions, any poor decisions made at this juncture could undermine both public and private information security.

Politicians, especially in frontier industries like information technology, often take the easy path of seeking massive sums to establish taxpayer funded research grants for politically favored cybersecurity initiatives, set up redundant cybersecurity agencies, programs, and subsidies. This is precisely what the Cybersecurity Enhancement Act will do, potentially steering cybersecurity research away from its natural, safer, course.

Vastly expanding federal grants, fleets of scholarships and government-induced Ph.D.s in computer security is not the same as actually bolstering security, nor is there any reason the private sector cannot fund the training of its own such personnel or provide application-specific training as needed. Moreover, many serious security problems are not matters of new training but simply of embracing security “best practices” that already exist.

The Cybersecurity Enhancement Act amounts to pork, and the private sector can and should fund the training of America’s security experts. Online security is an immensely valuable industry today, and there is no shortage of private research incentive and potential profit.

Taxpayer-funded scholarships have already been extended to universities in countless respects, and incentives already abound for students to pursue technology careers. These new programs can easily grow beyond the proposed, already-generous bounds.

It’s beyond doubt that online security problems exist. Yet the tendency of cybersecurity today to be seen as an increasingly government-spearheaded function is worrisome. The taxpayer-funding approach can benefit some sectors and companies at the expense of competition and of computer security itself. Federal spending and intervention may encourage market distortion by skewing private investment decisions, or promoting one set of technologies or class of providers at the expense of others

We need better digital equivalents of barbed wire and door locks, which private companies are constantly competing to improve. While government law enforcement agencies have a necessary role to play in investigating and punishing intrusions on private networks and infrastructure, government must coexist with, rather than crowd out, private sector security technologies. Otherwise we become less secure, not more.

A substantial government role invariably grows into an irresistible magnet for lobbyists and the creation of bloated “research centers” and could all too easily become the locus for establishing sub-optimal government authority over our most vulnerable frontier technologies and sciences.

The solution? Enhancing private sector cybersecurity practices.

Both suppliers and customers in the high-tech sector increasingly demand better security from all players. Improving private incentives for information sharing is at least as important as greater government coordination and investment to ensure security and critical infrastructure protection. That job will entail liberalizing critical infrastructure assets—like telecommunications and electricity networks—and relaxing antitrust constraints so firms can coordinate information security strategies and enhance reliability of critical infrastructure through the kind of “partial mergers” that are anathema to today’s antitrust enforcers.

The future will deliver authentication technologies far more capable than those of today. Like everything else in the market, security technologies—from biometric identifiers to firewalls to network monitoring to encrypted databases—benefit from competition. Private cybersecurity initiatives will also gradually move us toward thriving liability and insurance markets, to help address the lack of authentication and inability to exclude bad actors that are at the root of today’s vulnerabilities.

Security is an industry unto itself, let’s not turn it into bureaucracy.

What do you think?

Thursday, January 21, 2010

Data Hung Out to Dry

Posted by Mark Brousseau

A new survey reveals that in the last year, 4,500 memory sticks have been forgotten in people’s pockets as they take their clothes to be washed at the local dry cleaners.

However, when compared with the same study twelve months ago, the number of these devices languishing forgotten in people’s pockets has halved, and yet it’s still a staggering number of possible data breaches.

However, the study sponsor, CREDANT Technologies, has a theory that this decline is likely to be a change in users’ habits as opposed to a significant breakthrough in people’s vigilance. In fact, its experience on the frontline of this battle is that users are now downloading information onto smartphones and netbooks, which have boomed in popularity in the last year, so although on the surface the decline looks promising in reality the situation has just been spread across a multitude of other devices.

Sean Glynn, vice president and chief marketing officer at Credant Technologies said “Although this study shows a positive drop in the number of lost memory sticks we would urge users to take more care than ever not to download unprotected customer details and other sensitive information that if lost could lead to a security breach, especially now there are harsh fines afoot.”

Concluding Sean Glynn said “This survey is just one illustration of the stark truth that device losses are happening everywhere, everyday, worldwide. Organizations want to leverage the business benefits of mobile computing and provide their employees the flexibility to work wherever and whenever they want to. However, this must be balanced with the requirement of protecting the organizations data. If sensitive or valuable data is being carried then people should protect it with encryption to prevent unauthorised access at any point - as it could easily end up in the wrong hands.”

Saturday, January 9, 2010

Greatest Cyber Risks

Posted by Mark Brousseau

More than 40 percent of executives polled by Deloitte believe remote internet access to corporate systems, embedded malware in computers, applications and devices, and little visibility into the security protocols of suppliers and business units are the greatest cyber risks today.

"Cyber attacks today are not only about identity theft, but about stealing information behind companies' firewalls," said Mark White, principal, Deloitte Consulting LLP. "An entire underground economy has been built for the purpose of stealing, packaging, and reselling electronic information. Never before in history has the threat landscape been as deeply penetrated or more rapidly evolving. Never before have nations, corporations or individuals been more electronically exploited."

Richard Baich, a principal in Deloitte & Touche LLP's Security & Privacy practice, noted that security programs need to be strengthened as it has become increasingly evident that criminals with advanced cyber skills continuously invent new and insidious ways to perpetrate criminal acts. "The cyber crime landscape has evolved into a set of highly specialized criminal products and services that are able to target specific organizations, regions, and customer profiles by using a sophisticated set of malware exploits and anonymization systems, which routinely evade present-day security controls," said Baich.

Baich also stated that cyber criminals are now able to target specific individuals within an organization, such as a payroll clerk, and misuse that role to steal information for direct monetary gain. Nation-states are also able to recruit and leverage cyber criminal resources to target organizations or other nations for the purposes of espionage, monetary gain, or to gain military advantage.

"This leaves executives asking what they can do to quickly identify and contain malware and then protect their data. This is after they already spent a good deal of money on traditional protection programs," said Baich. "Companies should consider establishing cyber threat intelligence programs as well as leveraging existing technology and architecture investments to help detect and prevent these problems."

"Data is more valuable than money. Once money is spent it is gone. Data can be reused and can give you the ability to access online banking applications, use credit cards and penetrate firewalls over and over. A famous bank robber from the 1900s was asked why he robbed banks. He said 'because that is where the money is.' Cyber criminals today go to where the data is, because it allows them to access money. Executives need to develop cyber programs to stay ahead of criminals and stop old cat and mouse games," added Baich.

Other polling results included:

... Only 2.8 percent of the participants indicated they did not need a type of cyber threat intelligence or detection program.
... 62.2 percent of respondents did not know how their organization understands what data is leaving the company's network, though 14.1 percent did confirm that their organizations were using a data loss prevention solution.
... 41.4 percent reported that they did not know how their organizations found compromised devices inside of their network.
... More than a quarter (27.4 percent) indicated their organizations rely on some type of antivirus and intrusion detection system.

Peter Makohon, senior manager, Deloitte & Touche LLP, said that "cyber crime may already be in their neighborhoods" and cited the following issues facing executives:

... Current signature-based information security controls are not effective against sophisticated, cyber threats and exploits, which are evolving at a phenomenal rate.
... Companies lack the automated systems and skilled analysts to rapidly analyze, identify, contain, analyze, and remediate compromised devices.
... Information provided by various cyber intelligence sources is often outdated and high level; therefore, companies cannot take effective counter-actions based on that information alone.
... Organizations lack expertise, resources, technology, and process capabilities for taking timely action on these near real-time cyber threats.

What do you think? Post your comments below.

Monday, June 15, 2009

Credit Card Security Problems

Posted by Mark Brousseau

An interesting article from the Associated Press on how lax requirements leave consumer data at risk of attack by hackers:

Weak security enables credit card hacks
By JORDAN ROBERTSON
AP Technology Writer

Every time you swipe your credit card and wait for the transaction to be approved, sensitive data including your name and account number are ferried from store to bank through computer networks, each step a potential opening for hackers.

And while you may take steps to protect yourself against identity theft, an Associated Press investigation has found the banks and other companies that handle your information are not being nearly as cautious as they could.

The government leaves it to card companies to design security rules that protect the nation's 50 billion annual transactions. Yet an examination of those industry requirements explains why so many breaches occur: The rules are cursory at best and all but meaningless at worst, according to the AP's analysis of data breaches dating to 2005.

It means every time you pay with plastic, companies are gambling with your personal data. If hackers intercept your numbers, you'll spend weeks straightening your mangled credit, though you can't be held liable for unauthorized charges. Even if your transaction isn't hacked, you still lose: Merchants pass to all their customers the costs they incur from fraud.

More than 70 retailers and payment processors have disclosed breaches since 2006, involving tens of millions of credit and debit card numbers, according to the Privacy Rights Clearinghouse. Meanwhile, many others likely have been breached and didn't detect it. Even the companies that had the payment industry's top rating for computer security, a seal of approval known as PCI compliance, have fallen victim to huge heists.

Companies that are not compliant with the PCI standards - including one in 10 of the medium-sized and large retailers in the United States - face fines but are left free to process credit and debit card payments. Most retailers don't have to endure security audits, but can evaluate themselves.

Credit card providers don't appear to be in a rush to tighten the rules. They see fraud as a cost of doing business and say stricter security would throw sand into the gears of the payment system, which is built on speed, convenience and low cost.

That is of little consolation to consumers who bet on the industry's payment security and lost.

It took four months for Pamela LaMotte, 46, of Colchester, Vt., to fix the damage after two of her credit card accounts were tapped by hackers in a breach traced to a Hannaford Bros. grocery store.

LaMotte, who was unemployed at the time, says she had to borrow money from her mother and boyfriend to pay $500 in overdraft and late fees - which were eventually refunded - while the banks investigated.

"Maybe somebody who doesn't live paycheck to paycheck, it wouldn't matter to them too much, but for me it screwed me up in a major way," she said. LaMotte says she pays more by cash and check now.

It all happened at a supermarket chain that met the PCI standards. Someone installed malicious software on Hannaford's servers that snatched customer data while it was being sent to the banks for approval.

Since then, hackers plundered two companies that process payments and had PCI certification. Heartland Payment Systems lost card numbers, expiration dates and other data for potentially hundreds of millions of shoppers. RBS WorldPay Inc. got taken for more than 1 million Social Security numbers - a golden ticket to hackers that enables all kinds of fraud.

In the past, each credit card company had its own security rules, a system that was chaotic for stores.

In 2006, the big card brands - Visa, MasterCard, American Express, Discover and JCB International - formed the Payment Card Industry Security Standards Council and created uniform security rules for merchants.

Avivah Litan, a Gartner Inc. analyst, says retailers and payment processors have spent more than $2 billion on security upgrades to comply with PCI. And the payment industry touts the fact that 93 percent of big retailers in the U.S., and 88 percent of medium-sized ones, are compliant with the PCI rules.

That leaves plenty of merchants out, of course, but the main threat against them is a fine: $25,000 for big retailers for each month they are not compliant, $5,000 for medium-sized ones.

Computer security experts say the PCI guidelines are superficial, including requirements that stores run antivirus software and install computer firewalls. Those steps are designed to keep hackers out and customer data in. Yet tests that simulate hacker attacks are required just once a year, and businesses can run the tests themselves.

"It's like going to a doctor and getting your blood pressure read, and if your blood pressure's good you get a clean bill of health," said Tom Kellermann, a former senior member of the World Bank's Treasury security team and now vice president of security awareness for Core Security Technologies, which audited Google's Internet payment processing system.

Merchants that decide to hire an outside auditor to check for compliance with the PCI rules need not spend much. Though some firms generally charge about $60,000 and take months to complete their inspections, others are far cheaper and faster.

"PCI compliance can cost just a couple hundred bucks," said Jeremiah Grossman, founder of WhiteHat Security Inc., a Web security firm. "If that's the case, all the incentives are in the wrong direction. The merchants are inclined to go with the cheapest certification they need."

For some inspectors, the certification course takes just one weekend and ends in an open-book exam. Applicants must have five years of computer security experience, but once they are let loose, there's little oversight of their work. Larger stores take it on themselves to provide evidence to auditors that they comply with the rules, leaving the door open for mistakes or fraud.

And retailers with fewer than 6 million annual card transactions - a group comprising more than 99 percent of all retailers - do not even need auditors. They can test and evaluate themselves.
At the same time, the card companies themselves are increasingly hands-off.

Two years ago, Visa scaled back its review of inspection records for the payment processors it works with. It now examines records only for payment processors with computer networks directly connected to Visa's.

In the U.S., that means fewer than 100 payment processors out of the 700 that Visa works with are PCI-compliant.

Visa's head of global data security, Eduardo Perez, said the company scaled back its records review because it took too much work and because the PCI standards have improved the industry's security "considerably."

"I think we've made a lot of progress," he said. "While there have been a few large compromises, there are many more compromises we feel we've helped prevent by driving these minimum requirements."

Representatives for MasterCard, American Express, Discover and JCB - which, along with Visa, steer PCI policy - either didn't return messages from the AP or directed questions to the PCI security council.

PCI's general manager, Bob Russo, said inspector certification is "rigorous." Yet he also acknowledged that inconsistent audits are a problem - and that merchants and payment processors who suffered data breaches possibly shouldn't have been PCI-certified. Those companies also might have easily fallen out of compliance after their inspection, by not installing the proper security updates, and nobody noticed.

The council is trying to crack down on shoddy work by requiring annual audits for the dozen companies that do the bulk of the PCI inspections. Smaller firms will be examined once every three years.

Those reviews merely scratch the surface, though. Only three full-time staffers are assigned to the task, and they can't visit retailers themselves. They are left to review the paperwork from the examinations.

The AP contacted eight of the biggest "acquiring banks" - the banks that retailers use as middlemen between the stores and consumers' banks. Those banks are responsible for ensuring that retailers are PCI compliant. Most didn't return calls or wouldn't comment for this story.

Mike Herman, compliance managing director for Chase Paymentech, a division of JPMorgan Chase, said his bank has five workers reviewing compliance reports from retailers. Most of the work is done by phone or e-mail.

"We have faith in the certification process, and we really haven't doubted the assessors' work," Herman said. "It's really the merchants that don't engage assessors; those get a little more scrutiny."

He defended the system: "Can you imagine how many breaches we'd have and how severe they'd be if we didn't have PCI?"

Supporters of PCI point out nearly all big and medium-sized retailers governed by the standard now say they no longer store sensitive cardholder data. Just a few years ago they did - leaving credit card numbers in databases that were vulnerable to hackers.

So why are breaches still happening? Because criminals have sharpened their attacks and are now capturing more data as it makes its way from store to bank, when breaches are harder to stop.

Security experts say there are several steps the payment industry could take to make sure customer information doesn't leak out of networks.

Banks could scramble the data that travels over payment networks, so it would be meaningless to anyone not authorized to see it.

For example, TJX Cos., the chain that owns T.J. Maxx and Marshalls and was victimized by a breach that exposed as many as 100 million accounts, the most on record, has tightened its security but says many banks won't accept data in encrypted form.

PCI requires data transmitted across "open, public networks" to be encrypted, but that means hackers with access to a company's internal network still can get at it. Requiring encryption all the time would be expensive and slow transactions.

Another possibility: Some security professionals think the banks and credit card companies should start their own PCI inspection arms to make sure the audits are done properly. Banks say they have stepped up oversight of the inspections, doing their own checks of questionable PCI assessment jobs. But taking control of the whole process is far-fetched: nobody wants the liability.

PCI could also be optional. In its place, some experts suggest setting fines for each piece of sensitive data a retailer loses.

The U.S. might also try a system like Europe's, where shoppers need a secret PIN code and card with a chip inside to complete purchases. The system, called Chip and PIN, has cut down on fraud there (because it's harder to use counterfeit cards), but transferred it elsewhere - to places like the U.S. that don't have as many safeguards.

A key reason PCI exists is that the banks and card brands don't want the government regulating credit card security. These companies also want to be sure transactions keep humming through the system - which is why banks and card companies are willing to put up with some fraud.

"If they did mind, they have immense resources and could really change things," said Ed Skoudis, co-founder of security consultancy InGuardians Inc. and an instructor with the SANS Institute, a computer-security training organization. Skoudis investigates retail breaches in support of government investigations. "But they don't want to strangle the goose that laid the golden egg by making it too hard to accept credit cards, because that's bad for everybody."

Tuesday, August 19, 2008

Are We Vulnerable to Identity Theft?

Posted by Mark Brousseau

An interesting article from The Boston Globe about identity theft:

The breach

A loose-knit ring of hackers stole credit card data from unsuspecting US retailers. Though 11 people have been indicted, experts say the case shows how sophisticated identity-theft schemes have become.

By Ross Kerber, Globe Staff August 17, 2008

Five years ago, Albert Gonzalez allegedly used an unsecured radio link to tap into the computers of a BJ's Wholesale Club store in Miami and access customer credit-card numbers.

It was a simple trick, but it was only the beginning.

From that first break-in, Gonzalez and a ring of accomplices flew up the learning curve, prosecutors charge. They wirelessly broke into the computer networks of other stores including those operated by OfficeMax Inc., Boston Market Corp., Barnes & Noble Inc., and TJX Cos. And they apparently learned to decrypt customer PIN numbers, install sophisticated software, and park payment card data in offshore databases, in what the Justice Department on Aug. 5 called the biggest hacking and identity-theft case it has ever prosecuted - compromising more than 40 million credit and debit card accounts.

Court filings and interviews with investigators paint a picture of an international ring of 11 loosely knit conspirators from China to Ukraine, and show how quickly such criminal groups can graduate to increasingly sophisticated schemes to exploit the vulnerabilities that remain in the payment card network.

Despite the arrests, Gartner Inc. technology analyst Avivah Litan said it's too soon to relax. Though prosecutors tied the ring to some of the biggest breaches in this decade, their cases don't mention other intrusions such as one of Maine grocer Hannaford Bros. earlier this year.

Also worrisome, Litan said, was that the group allegedly was able to use fake ATM cards with real account numbers to withdraw money from bank machines, indicating they cracked the encryption of PIN numbers.

"The implications are ominous," Litan said. While many banks and retailers have begun using tougher encryption since then, some companies are still on the older standards that she called "inherently vulnerable."

Another technology analyst, Mary Monahan of Javelin Strategy & Research, said more stores have met data-security standards spelled out by Visa and MasterCard since the time of breaches like the one at TJX in 2005, which should make customers' card numbers more secure. Still, Hannaford met those standards at the time of its breach, illustrating how criminal tactics have evolved to stay ahead of defensive measures.

One lesson from this months' indictments, Monahan said, is how the hackers learned to become more sophisticated and global. "You can see that they're developing their skills over time, and transferring skills among one another," she said.

A defense attorney for Gonzalez, Rene Palomino, said his client will plead not guilty to the charges. He described Gonzalez, 27, as a self-taught computer consultant who first met several of the other defendants online.

Former informantIronically, the story of how the group of accomplices came to be begins with Gonzalez helping law enforcement officials. Though arrested in connection with theft from an automated teller machine in 2003, Gonzalez soon became a key Secret Service informant and even gave the agency security lectures, Palomino said. Gonzalez was best known for helping officials bring charges against a group known as the "Shadowcrew" after one of the online message boards that served as a marketplace for stolen payment card numbers - 1.7 million of them in all, prosecutors would charge.

Despite serving as an informant, the Justice Department claims, Gonzalez also began "wardriving" in the areas around US Highway 1 in Miami, according to this month's indictments. The term refers to the tactic of cruising in a vehicle with a laptop computer to spot unsecured connections to wireless systems maintained by various stores.

Gonzalez' partner in the wireless probes allegedly was another twentysomething, Christopher Scott, who Palomino said Gonzalez had met in online circles in Miami. Scott's attorney said he hasn't yet entered a plea.

According to the indictments, the pair first got lucky in 2003 at a BJ's Wholesale Club store, which wasn't using encryption software to protect customers' data, and accessed the account numbers of payment cards used by customers.

The next year Scott and another accomplice, described only by the acronym "J.J.," went further. Tapping into a similar access point at an OfficeMax store near the highway, they located data including customers' encrypted PIN numbers punched in when they used debit cards. They turned the data over to Gonzalez, who allegedly sent it to an unnamed coconspirator for decryption.

Filings and investigators say other stores hit by the ring included Barnes & Noble and Sports Authority, many in the Miami area. The indictments suggest the biggest breach began in July 2005 when Scott compromised two wireless access points of Marshalls' stores in the Miami area, both operated by Framingham retailer TJX Cos.

Soon the group was downloading payment card data from TJX's home servers. By the following May, in 2006, Scott had graduated to setting up a "virtual private network" connection to a TJX server, making it harder to detect the intrusion.

Next, Gonzalez brought in a Ukrainian, Maksym Yastremskiy, who prosecutors describe as an international trafficker of stolen card data who sold it on the Web. Via instant message in May 2006, Gonzalez allegedly asked Yastremskiy for help finding an undetectable "sniffer" program that would pick up customer card numbers and provide a feed of stolen data. Several days later, Scott, Gonzalez, and others installed sniffer programs onto a TJX server - likely provided by Yastremskiy, the indictment implies.

Craig Magaw, special agent in charge of the Secret Service's criminal investigative division, which led the probe of the hacker ring, said he had no evidence that Gonzalez and Yastremskiy ever met or spoke outside of their electronic communications. But their virtual connections, he said in an interview, were a common trait to criminal rings using web-based message boards.

"It's the usual M.O., where they can go to be anonymous and help each other further their activity," he said. "It's not just that they're selling the information but, if you go on these [message] boards, it's how to do compromises and giving advice. It's the criminals' playground."

Authorities arrested Yastremskiy in Turkey a year ago while he was visiting a resort. The US Postal Inspection Service confirmed to the Globe at the time that he was tied to the TJX probe.

Since then, neither the Justice Department nor Turkish officials have provided contact information for Yastremskiy or an attorney representing him.

Yastremskiy's laptop provided a trove of details including an e-mail tie to Gonzalez, Magaw said. Gonzalez was arrested May 7 at a hotel room in Miami in connection with a related hacking case to which he has also denied wrongdoing. Court papers show officials seized from him three laptop computers, and a Glock 27 automatic pistol.

Encoding blank cardsIn addition to showing how the group allegedly stole information, the indictments also shed light on how the ring may have used the data on the streets.

In 2005 and 2006, Gonzalez allegedly sold large amounts of payment card data to a person named only by the initials "J.W." This person allegedly encoded the information on the magnetic stripes of blank plastic payment cards, then used the cards to withdraw hundreds of thousands of dollars from ATMs and split the money with Gonzalez. Another unnamed San Diego purchaser also bought 100 blank payment cards from an individual in China connected to Yastremskiy in 2005, prosecutors charge.

Both examples recall cases in Florida last year in which state prosecutors won guilty pleas from six people who misused card numbers stolen from TJX. After obtaining blank cards magnetically encoded with the stolen numbers, they took the plastic to various Wal-Mart stores in Florida to buy gift cards that could be used like cash. In turn they used those cards to buy $8 million worth of expensive electronics, jewelry, and other items, officials said, returning some items for cash.

Details of how to encode blank cards with stolen account numbers are among the topics typically discussed on underground websites, security experts say; the Secret Service estimates there are 20 message boards or websites in the United States and overseas where criminals sell stolen numbers, trade tips, and form bonds like those between Gonzalez and Yastremskiy. Was theirs like an underground university? "I guess, but there's no diplomas coming out of there," Magaw said.

Or, as Massachusetts US Attorney Michael Sullivan put at a press conference announcing the indictments on Aug. 5: "There's no evidence that any of these people had PhDs."

Globe staff reporter Marion Schmidt contributed to this report. Ross Kerber can be reached at kerber@globe.com.

Thursday, August 7, 2008

Shocking Internet Hack

Posted by Mark Brousseau

An interesting article from newsday.com about the incredible scope of a recent Internet hack case:

Feds astounded by volume, scope of Internet hack case
BY KEIKO MORRIS
mailto:keiko.morris@newsday.com?subject=Newsday.com
August 7, 2008

The sheer volume of the credit and debit card numbers stolen was astounding as was the far-flung cast of multinational characters in one of the largest Internet hacking and fraud cases federal prosecutors say they've seen in this country.

And while many credit card users are protected from full or partial liability, the scope of the impact of the mammoth case that snagged 11 people in the heist of more than 40 million card numbers is unknown.

For retailers, banks and credit card companies, Tuesday's announcement by federal prosecutors that they had unraveled a case stretching back years, highlighted the constant battle against Internet criminals. And although most consumers won't bear the burden immediately, the price of Internet fraud to banks and retailers could end up costing customers in the long run, technology security experts say.

"... The overall cost is high and you can bet your bottom dollar that that cost will get passed on to us, Joe Average card holder," said Ed Moyle, manager at CTG, an Internet technology firm in Amherst, N.H.

The unveiling of the ring and the numerous charges, including fraud and identity theft, was reason for retailers to rejoice, industry experts said. The conspiracy, allegedly led by Albert "Segvec" Gonzalez, 27, of Miami, hit some of the biggest retailers, including TJX Cos., BJ's Wholesale Club, OfficeMax, DSW and Barnes & Noble, among others."

This was a very targeted attack on our industry," said Scott Krugman, spokesman for the National Retail Federation. "It took a very sophisticated network to do this."

The incidents in which the defendants -- hailing from Belarus and China and Ukraine -- found wireless access points to steal credit and debit card numbers date to 2003. TJX Cos. Inc. based in Framingham, Mass., discovered its computer system allegedly had been attacked by the defendants in 2006. Shoe retailer DSW was hit in 2005. Most of the major credit card companies and banks contacted declined to comment about the case specifically but said they know of the investigation and they have procedures to secure information. For card issuers, the cost to reissue cards is significant and, eventually will get passed down to consumers, Moyle said.

"The sheer number of retailers attacked by these cyber criminals demonstrates the much broader challenges in protecting sensitive customer data from this increasing threat," Sherry Lang, a TJX spokeswoman, said in a statement. "... Broader action beyond retailers alone is required to protect consumer data. Banks and the U.S. payment card industry must join retailers and work together."

Technology security experts said retailers and credit card companies fight a constant battle against cyber crimes and have made strides over the years to comply with technical standards set by the PCI Security Standards Council, a group founded by five of the major credit card companies, to protect information systems.Retailers worry more about their credibility with consumers and their confidence in using the electronic systems, said Brit Beemer, chairman of the market research firm America's Research Group.

The idea that more than 40 million card numbers were stolen from major national chains will make consumers wary, but both retail and technology security experts said they were skeptical the case will change the way consumers used their credit or debit cards.

Both experts and prosecutors said consumers should check their accounts as well as their credit reports and set up fraud alerts if they believe their information has been stolen. Consumers face the hassle of requesting new cards or accounts but institutions' zero-liability policies mean that consumers won't suffer the losses.

"They have zero-liability protection so that definitely helps them get over those fears associated with data breaches," said Bruce Cundiff, director of payments research at Javelin Strategy & research in San Francisco.

What do you think is the solution to these types of hacks?

Post your comment below.

Monday, July 7, 2008

ATM Hack Reveals Security Woes

Posted by Mark Brousseau

An interesting article from the Associated Press about ATM security challenges:

Citibank ATM breach reveals PIN security problems
By JORDAN ROBERTSON
The Associated PressTuesday, July 1, 2008; 4:39 PM

SAN JOSE, Calif. -- Hackers broke into Citibank's network of ATMs inside 7-Eleven stores and stole customers' PIN codes, according to recent court filings that revealed a disturbing security hole in the most sensitive part of a banking record.

The scam netted the alleged identity thieves millions of dollars. But more importantly for consumers, it indicates criminals were able to access PINs -- the numeric passwords that theoretically are among the most closely guarded elements of banking transactions -- by attacking the back-end computers responsible for approving the cash withdrawals.

The case against three people in U.S. District Court for the Southern District of New York highlights a significant problem.

Hackers are targeting the ATM system's infrastructure, which is increasingly built on Microsoft Corp.'s Windows operating system and allows machines to be remotely diagnosed and repaired over the Internet. And despite industry standards that call for protecting PINs with strong encryption -- which means encoding them to cloak them to outsiders -- some ATM operators apparently aren't properly doing that. The PINs seem to be leaking while in transit between the automated teller machines and the computers that process the transactions.

"PINs were supposed be sacrosanct _ what this shows is that PINs aren't always encrypted like they're supposed to be," said Avivah Litan, a security analyst with the Gartner research firm. "The banks need much better fraud detection systems and much better authentication."

It's unclear how many Citibank customers were affected by the breach, which extended at least from October 2007 to March of this year and was first reported by technology news Web site Wired.com. The bank has nearly 5,700 Citibank-branded ATMs inside 7-Eleven Inc. stores throughout the U.S., but it doesn't own or operate any of them.

That responsibility falls on two companies: Houston-based Cardtronics Inc., which owns all the machines but only operates some, and Brookfield, Wis.-based Fiserv Inc., which operates the others.

A critical issue in the investigation is how the hackers infiltrated the system, a question that still hasn't been answered publicly.

All that's known is they broke into the ATM network through a server at a third-party processor, which means they probably didn't have to touch the ATMs at all to pull off the heist.

They could have gained administrative access to the machines -- which means they had carte blanche to grab information -- through a flaw in the network or by figuring out those computers' passwords. Or it's possible they installed a piece of malicious software on a banking server to capture unencrypted PINs as they passed through.

What that means for consumers is that their PINs were stolen from machines that showed no signs of tampering they could detect. In previous PIN thefts, thieves generally took steps that might draw notice -- sending "phishing" e-mails, for example, or installing false-front keypads or even tiny cameras on ATMs.

Getting the PINs is a key step for identity thieves. It lets criminals encode stolen account information onto blank ATM cards and withdraw piles of cash from compromised accounts.

Don Jackson, director of threat intelligence for SecureWorks Inc., said he has seen an "alarming" spike in the number of attacks on back-end computers for ATM networks over the past year.

"This was fairly large, but I don't think it's anything out of the ordinary -- these kinds of scams go on every day," Jackson said. "What makes this case unique is the sheer luck of happening upon these guys and catching them red-handed. But there are a whole lot of other ATM and PIN compromises going on that aren't reported."

The alleged plot is outlined in court papers supporting the prosecution of three people _ Yuriy Rakushchynets, Ivan Biltse and Angelina Kitaeva. They were indicted in March on two counts each of conspiracy and fraud. Prosecutors say their activities generated at least $2 million in illegal profits.

Defense lawyers for all three people did not return calls for comment, and it was not clear where they had been living. The main defendant, Rakushchynets, was described as having Michigan and Florida's driver licenses in a February FBI affidavit for an arrest warrant.

Citibank, part of Citigroup Inc., has declined to comment on the technique or how many customers' accounts were compromised. It said it notified affected customers and issued them new debit cards.

"We want our customers to know that, consistent with legal requirements, we do not hold them responsible for fraudulent activity in their accounts," the bank said in a statement.

Cardtronics said it is cooperating with authorities but otherwise declined to comment. Fiserv spokeswoman Melanie Tolley said the intrusion didn't happen on Fiserv's servers.

"Fiserv," she said, "is confident in the integrity and security of our system."

Wednesday, July 2, 2008

Data Breaches Rising

Posted by Mark Brousseau

An interesting article from the Washington Post on the rising number of data breaches:

Data Breach Reports Up 69 Percent in 2008
By Brian Krebs


Businesses, governments and universities reported a record number of data breaches in the first half of this year, a 69 percent increase over the same period in 2007 driven by a spike in data thefts attributed to employees and contractors, according to an analysis by identity theft experts.

The San Diego-based Identity Theft Resource Center tracked 342 data breach reports from Jan. 1 to June 27. Nearly 37 percent of reports came from businesses -- an increase from almost 29 percent last year.

Data breach reports from health care providers (14.9 percent of the total) and banks (10 percent) continued to rise, while the share of breaches from educational institutions (21.3 percent of the total) government entities and the military (17 percent) declined for the third year in a row, the ITRC found.

Hacking was the least-cited cause of data breaches in the first six months of 2008 (11.7 percent of the total). Instead, lost or stolen laptops and other digital storage media remain the most frequently cited cause of data breaches, accounting for more than 20 percent of all reported cases, the ITRC found. The inadvertent posting of personal and financial data online prompted roughly 15 percent of the data breach disclosures.

While the share of breaches due to data on the move fell nearly eight percent from last year, that slack was picked up by insider theft. Data breaches due to information stolen by someone inside the company increased from just six percent of the total in 2007 to nearly 16 percent so far this year. Another 13.5 percent of breaches came from subcontractors who lost or stole their clients' customer data.

The 342 breaches the ITRC studied from this year involved almost 17 million consumer records. But ITRC founder Linda Foley said the true number of records jeopardized by those breaches is likely far higher, because in nearly 40 percent of the breaches the affected entity has not yet disclosed how many consumer records were lost or stolen.

Some 44 states and the District of Columbia now have laws requiring entities that suffer a data loss or breach to alert affected consumers (according to the ITRC, the states without data breach notification laws are Alaska, Alabama, Iowa, Kentucky, Mississippi and South Dakota). But Foley said only three states -- Maryland, New Hampshire and Wisconsin - require reporting to state officials and routinely publish that information online.

Breach notices filed with those three states have in many cases amounted to the first public disclosure of data breaches, but they also expose the gaps in those disclosure laws, Foley said.

On June 9, for example, the United Transportation Union Insurance Association notified the Maryland Attorney General that the loss of an undisclosed number of laptops jeopardized the names and Social Security numbers of 394 Maryland residents. However, the association has not yet said how many consumer records from all states were included on the missing laptops.

On May 8, Saks Inc. notified Maryland that the theft of four laptops had resulted in the loss of the name, address and Saks Fifth Avenue credit card numbers belonging to 2,391 Maryland residents. Saks similarly told the New Hampshire Attorney General's office that the breach affected 163 of that state's residents. Saks has not yet said how many customers nationwide may have been impacted by the lost laptops.

While a data breach may be reported as a single incident, it often masks the true number of institutions affected by the incident. This is most often the case with contractor breaches, such as one first publicly reported to the Maryland Attorney General's office on June 13. That notification was sent by attorneys for technology news media outlet CNET Networks, who said they were told that computer equipment stolen from Colt Express Outsourcing Services Inc., a California company that administers benefit plans to businesses across the country, resulted in the loss of records bearing the names, dates of birth and Social Security numbers of 6,500 CNET current and former employees and dependents.

Colt officials have declined to say how many total consumer records may have been affected, but several other businesses have reported receiving notifications from Colt over the past few weeks.

"It's a little like if you see a major pileup on the freeway, there's that one car that caused the whole accident, and then there are bunch of other innocent third parties that are affected due to the domino effect," Foley said.

Saturday, March 29, 2008

Plan Would Empower Fed

Posted by Mark Brousseau

An interesting article in yesterday's New York Times:

Treasury Dept. Plan Would Give Fed Wide New Power

By EDMUND L. ANDREWS

WASHINGTON — The Treasury Department will propose on Monday that Congress give the Federal Reserve broad new authority to oversee financial market stability, in effect allowing it to send SWAT teams into any corner of the industry or any institution that might pose a risk to the overall system.

The proposal is part of a sweeping blueprint to overhaul the nation’s hodgepodge of financial regulatory agencies, which many experts say failed to recognize rampant excesses in mortgage lending until after they set off what is now the worst financial calamity in decades.

Democratic lawmakers are all but certain to say the proposal does not go far enough in restricting the kinds of practices that caused the financial crisis. Many of the proposals, like those that would consolidate regulatory agencies, have nothing to do with the turmoil in financial markets. And some of the proposals could actually reduce regulation.

According to a summary provided by the administration, the plan would consolidate an alphabet soup of banking and securities regulators into a powerful trio of overseers responsible for everything from banks and brokerage firms to hedge funds and private equity firms.

While the plan could expose Wall Street investment banks and hedge funds to greater scrutiny, it carefully avoids a call for tighter regulation.

The plan would not rein in practices that have been linked to the housing and mortgage crisis, like packaging risky subprime mortgages into securities carrying the highest ratings.

The plan would give the Fed some authority over Wall Street firms, but only when an investment bank’s practices threatened the entire financial system.

And the plan does not recommend tighter rules over the vast and largely unregulated markets for risk sharing and hedging, like credit default swaps, which are supposed to insure lenders against loss but became a speculative instrument themselves and gave many institutions a false sense of security.

Parts of the plan could reduce the power of the Securities and Exchange Commission, which is charged with maintaining orderly stock and bond markets and protecting investors. The plan would merge the S.E.C. with the Commodity Futures Trading Commission, which regulates exchange-traded futures for oil, grains, currencies and the like.

The blueprint also suggests several areas where the S.E.C. should take a lighter approach to its oversight. Among them are allowing stock exchanges greater leeway to regulate themselves and streamlining the approval of new products, even allowing automatic approval of securities products that are being traded in foreign markets.

The proposal began last year as an effort by Henry M. Paulson Jr., secretary of the Treasury, to make American financial markets more competitive against overseas markets by modernizing a creaky regulatory system.

His goal was to streamline the different and sometimes clashing rules for commercial banks, savings and loans and nonbank mortgage lenders.

“I am not suggesting that more regulation is the answer, or even that more effective regulation can prevent the periods of financial market stress that seem to occur every 5 to 10 years,” Mr. Paulson will say in a speech on Monday, according to a draft. “I am suggesting that we should and can have a structure that is designed for the world we live in, one that is more flexible.”

Congress would have to approve almost every element of the proposal, and Democratic leaders are already drafting their own bills to impose tougher supervision over Wall Street investment banks, hedge funds and the fast-growing market in derivatives like credit default swaps.

But Mr. Paulson’s proposal for the Fed echoes ideas championed by Representative Barney Frank, the Massachusetts Democrat who is chairman of the House Financial Services Committee.

Both see the Fed overseeing risk across the entire financial spectrum, but Mr. Frank is likely to favor a stronger Fed role and to subject investment banks to the same rules that commercial banks now must follow, especially for capital reserves.

The Treasury plan would let Fed officials examine the practices and even the internal bookkeeping of brokerage firms, hedge funds, commodity-trading exchanges and any other institution that might pose a risk to the overall financial system.

That would be a significant expansion of the central bank’s regulatory mission.

When Fed officials agreed this month to rescue Bear Stearns, once the nation’s fifth-largest investment bank, they pointedly noted that the Fed never had the authority to monitor its financial condition or order it to bolster its protections against a collapse.

In two unprecedented moves, the Fed engineered a marriage between JPMorgan Chase and Bear Stearns, lending $29 billion to JPMorgan to prevent a Bear bankruptcy and a chain of defaults that might have felled much of the financial system.

For the first time since the 1930s, the Fed also agreed to let investment banks borrow hundreds of billions of dollars from its discount window, an emergency lending program reserved for commercial banks and other depository institutions.

But Mr. Paulson’s proposal would fall well short of the kind of regulation that Democrats have been proposing. Mr. Frank and other senior Democrats have argued that investment banks and other lightly regulated institutions now compete with commercial banks and should be subject to similar regulation, including examiners who regularly pore over their books and quietly demand changes in their practices.

In a recent interview, Mr. Frank said he realized the need for tighter regulation of Wall Street firms after a meeting with Charles O. Prince III, then chairman of Citigroup.

When Mr. Frank asked why Citigroup had kept billions of dollars in “structured investment vehicles” off the firm’s balance sheet, he recalled, Mr. Prince responded that Citigroup, as a bank holding company, would have been at a disadvantage because investment firms can operate with higher debt and lower capital reserves.

Senator Charles E. Schumer, Democrat of New York, has taken a similar stance.

“Commercial banks continue to be supervised closely, and are subject to a host of rules meant to limit systemic risk,” Mr. Schumer wrote in an op-ed article on Friday in The Wall Street Journal. “But many other financial institutions, including investment banks and hedge funds, are regulated lightly, if at all, even though they act in many ways like banks.”

Mr. Paulson’s proposal is likely to provoke bruising turf battles in Congress among agencies and rival industry groups that benefit from the current regulations.

Administration officials acknowledged on Friday that they did not expect the proposal to become law this year, but said they hoped it would help frame a policy debate that would extend well after the elections in November.

In a nod to the debacle in mortgage lending, the administration proposed a Mortgage Origination Commission to evaluate the effectiveness of state governments in regulating mortgage brokers and protecting consumers.

The bulk of the proposal, however, was developed before soaring mortgage defaults set off a much broader credit crisis, and most of the proposals are geared to streamlining regulation.

This plan would consolidate a large number of regulators into roughly three big new agencies.

Bank supervision, now divided among five federal agencies, would be led by a Prudential Financial Regulator, which could send examiners into any bank or depository institution that is protected by either federal deposit insurance or other federal backstops. It would eliminate the distinction between “banks” and “thrift institutions,” which are already indistinguishable to most consumers, and shut down the Office of Thrift Supervision.

Any effort to merge the Commodity Futures Trading Commission with the S.E.C. is likely to provoke battles.

Yet another proposal would, for the first time, create a national regulator for insurance companies, an industry that state governments now oversee.

Administration officials argue that a national system would eliminate the inefficiencies of having 50 different state regulators, who have jealously guarded their powers and are likely to fight any federal encroachment.

Arthur Levitt, a former S.E.C. chairman who has long pushed for stronger investor protection, said his first impression of the plan was positive. Even though the S.E.C.’s powers might be reduced, Mr. Levitt said, the plan would create a broader agency to regulate business conduct in all financial services.

“It’s a thoughtful document,” he said. “I’m intrigued by the fact that it puts an emphasis on investor protection, and that it establishes an agency specifically for that purpose, which would operate across all markets. I think that’s a very constructive first step.”

Monday, January 28, 2008

Lost Data A Worldwide Affair

By Mark Brousseau

If you think the challenges associated with securing sensitive data are confined to the United States, think again. The International Herald Tribune reports that Britain’s tax and customs service lost banking and personal data of 25 million people – nearly half the country’s population – when two computer disks went missing in the mail in November 2007.

The disks were sent to a government audit office through an internal postal service and weren’t tracked. They were missing for three weeks before the loss was reported. The disks contained details of more than 7 million families in Britain who claim a child benefit – a tax-free monthly payment available to everyone with children. The information on the disks included parents’ and children’s names, along with addresses, dates of birth, national insurance numbers and banking details. What do you think? E-mail me at m_brousseau@msn.com.